We encrypt what we hold and harden how we hold it — but the strongest safeguard is how little we ask for in the first place. No stored card numbers, no brokerage passwords, nothing sold to anyone.
Every request travels over HTTPS/TLS. A strict Content-Security-Policy and hardened response headers guard the app in your browser.
You’re kept signed in with an HTTP-only cookie — invisible to page scripts, so a cross-site script can’t read or steal it — and every write carries a CSRF header.
Lemma Analysis executes no trades and moves no money. Connecting a broker is optional and read-only — a key you issue and can revoke at the broker — so there is nothing here that could place an order.
We keep your email and what you choose to enter — nothing more. No card numbers, no brokerage passwords, no data sold to advertisers.
Security is a chain of specific, boring engineering choices — not a slogan. Here is what actually protects your account and your research, from the browser to the database.
All traffic between your browser and our servers is encrypted with TLS (HTTPS). We add a Content-Security-Policy and modern security headers so the page itself resists tampering and script injection.
Authentication uses an HTTP-only, same-site session cookie rather than a token in local storage. Because JavaScript cannot read it, a cross-site scripting bug cannot exfiltrate your session, and state-changing requests must carry an anti-CSRF header to be accepted.
Your account email, your password (only ever kept as a salted one-way hash — never in readable form), and the research data you create: portfolios you enter, watchlists, journal notes, and saved screens. If you connect a brokerage account, we also hold the read-only key you issued for it — encrypted, never returned in any response, never written to a log, and left out of your data export. That is the extent of it.
Subscriptions are handled by LemonSqueezy, our payment provider and merchant of record. Your card details are entered on their PCI-compliant checkout and never pass through — or get stored on — our servers.
The safest way to secure a trade is never to be able to place one. Lemma Analysis is a research terminal, not a broker — it helps you decide, then you act in your own brokerage account, entirely outside our reach.
We never connect to your bank, and a broker only if you ask — with a read-only key you issue there and can revoke there. Whether you enter holdings by hand, import a file or connect a broker, there is no way for us — or anyone who breached us — to move your money: a read-only key cannot place an order, and nothing here is built to try. It’s the same principle behind everything on this page: the capability we don’t have is the risk you don’t carry.
Some of the strongest guarantees are the ones about what does not happen.
Not to advertisers, not to data brokers, not to anyone. Our revenue is subscriptions alone, so there is no incentive to monetise you.
The platform doesn’t link to your bank, and it never asks for your broker password. If you connect a broker, you issue a read-only key yourself and can revoke it there at any moment; we store it encrypted, never show it again — not even to you — and delete it the moment you disconnect.
Card data lives with our PCI-compliant payment processor, not with us. We see a plan and a status, not your card.
Product analytics are cookieless and aggregate. There are no third-party advertising trackers following you off our site.
The service is operated from the Czech Republic, which places it squarely under the EU’s GDPR. That is a legal obligation we already carry — the right to access, export, correct and delete your data — not a certificate we bought.
The best way to comply with data-protection law is to collect little in the first place. We ask for what the product genuinely needs and nothing more, which shrinks both your exposure and our obligations.
You can view the data tied to your account, export it, and delete your account and its data at any time. How we collect, use and retain data is spelled out in full on our Privacy page.
The full detail lives in our Privacy Policy and Terms, and our approach to independence and transparency is set out on the About page.
We’d rather be honest than impressive. Lemma Analysis does not yet hold formal third-party certifications such as SOC 2 or ISO 27001 — those are a goal we’re working toward, not a badge we’ll pretend to have. What we do today is run our own security reviews of the application and its dependencies, keep the attack surface deliberately small, and fix issues as we find them.
Security is never finished, so we treat it as ongoing work rather than a one-time box to tick. If you’re a researcher and you find a weakness, we want to hear about it: email support@lemma-analysis.com and give us a reasonable window to fix it before any public disclosure. Responsible reports are always welcome.
Your data is encrypted in transit with TLS, your session is held in an HTTP-only cookie that page scripts cannot read, and your password is stored only as a salted one-way hash. Just as importantly, we deliberately store very little: your email and the research you create. We never sell your data, and never store your card number. Connecting a brokerage account is optional and read-only: you issue the key, you can revoke it at the broker, and we keep it encrypted and never show it again.
To a bank, never. To a broker, only if you ask us to, and only to read. Lemma Analysis is a research and analysis tool, not a broker: it executes no trades and cannot move your money. You can enter holdings by hand, import a file you exported, or connect a supported broker with a read-only key that you issue at the broker and can revoke there at any time. We never receive your brokerage login, and disconnecting deletes the key.
No. Subscriptions are processed by LemonSqueezy, a PCI-compliant payment provider and merchant of record. Your card details are entered on their secure checkout and never reach or get stored on our servers. We only ever see your plan and its status.
Yes. The service is operated from the Czech Republic and therefore falls under the EU’s GDPR. You have the right to access, export, correct and delete your personal data, and our Privacy page documents exactly what we collect and why.
Not today, and we would rather tell you that plainly than imply otherwise. Formal third-party certifications are a roadmap item, not a current claim. What we can point to now is the architecture: encrypted transport, hardened sessions, a salted password store, brokerage access that is read-only and revocable by you, no stored card data, and a policy of collecting as little as possible.
We welcome responsible disclosure. If you believe you have found a vulnerability, email us at support@lemma-analysis.com with the details and we will investigate promptly. Please give us a reasonable window to fix an issue before disclosing it publicly.
Free to start. No credit card. Nothing sold, ever.